← Field notes

Asking permission is a feature, not a failure

The instinct is to make the agent as autonomous as possible. That instinct is wrong, and the reason is not safety — it is trust.

There is a strong pull, when you build an agent, towards removing every stopping point. Each confirmation dialog feels like an admission that the thing does not really work. Surely the goal is that it just… goes?

I no longer think so. Not for safety reasons — though those are real — but because the confirmations turned out to be where the trust gets built.

The asymmetry nobody prices in

Work splits cleanly into two piles, and they are not equally risky:

Reversible. Reading, searching, drafting, summarising, filing, tidying, preparing. If it gets these wrong you shrug and delete something. The cost of a mistake is a few seconds of annoyance.

Irreversible. Sending, replying, spending, booking, deleting, sharing, anything a second human sees. If it gets these wrong, the cost is not a few seconds. It is a relationship, or a payment, or your reputation with someone whose good opinion you needed.

The asymmetry is enormous and it is not linear. A hundred correct drafts do not buy back one wrongly-sent email. So the rule became simple: be aggressive on the first pile, and never act alone on the second.

In practice that means she will happily read your whole inbox, work out what each thread needs, and write six replies. She will not send any of them.

This is faster, not slower

The objection is obvious — surely stopping to ask makes the whole thing pointless, because you are back in the loop.

But you are in the loop at a completely different altitude. Approving six drafted replies takes maybe ninety seconds. Writing six replies takes half an hour. And critically, you were going to read them anyway. Nobody sane lets software email their clients unsupervised and then never checks. The review was always going to happen; the only question is whether it happens before or after the email left the building.

Putting it before is strictly better, and it costs nothing, because that review is not extra work. It is the work you were already doing, moved slightly earlier, where it can still change the outcome.

Permission per tool, not per session

The other thing I got wrong early: a single “allow everything” switch.

It is the model everyone ships and it is useless, because it forces one decision that covers wildly different levels of risk. Nobody can meaningfully consent to that. You either say no to everything, or you say yes once and then quietly worry.

So access is granted a tool at a time, and each one can be pulled back without dismantling anything else. Calendar but not email. Email reading but not email sending. Files in one folder, not the whole disk. It is more work to build and more surface to explain, and it is the only version I would personally run.

Say what you did not do

The last piece, and the one I would put in every agent I ever build: the report has to include the refusals.

I didn’t touch the contract with the studio — it looked like a legal document and I didn’t want to guess.

That single line does more for trust than a completed task list, because it demonstrates judgment rather than throughput. It tells you the system has a model of its own limits. And it gives you the one thing an autonomous tool normally denies you: a clean seam where you can step in, having lost nothing.

An agent that never stops is not more capable. It is just harder to supervise, and eventually you stop leaving anything out for it at all.

She is not finished yet

Work Fairy is in private beta. Put your name down and you will hear when there is something to actually use.

One email when she is ready.